MISY 5325 FINAL EXAM QUESTIONS AND ANSWERS |
2026
Another term for data range and reasonableness checks is: - Answers - input validation
Which of the following is not one of the three primary objectives of controls? - Answers -
Eliminate
What changes plaintext data to ciphered data? - Answers - Encryption
A hacker wants to launch an attack on an organization. The hacker uses a tool to
capture data sent over the network in cleartext, hoping to gather information that will
help make the attack successful. What tool is the hacker using? - Answers - A packet
analyzer
Primary considerations for assessing threats based on historical data in your local area
are __________ and ___________. - Answers - weather conditions, natural disasters
In a SQL injection attack, an attacker can: - Answers - read sections of a database or a
whole database without authorization.
What does the principle of least privilege have in common with the principle of need to
know? - Answers - They both specify that users be granted access only to what they
need to perform their jobs.
An access control such as a firewall or intrusion prevention system cannot protect
against which of the following? - Answers - Social engineering
What is the purpose of nonrepudiation techniques? - Answers - To prevent people from
denying they took actions
Background checks, software testing, and awareness training are all categories of: -
Answers - procedural controls.
Ideally, when should you perform threat modeling? - Answers - Before writing an
application or deploying a system
You receive an email from someone named Bob in the IT department who needs to
access your login information for a scheduled internal vulnerability assessment. You
know an assessment is taking place because your manager notified your group last
week. Normally, you wouldn't give your password or other login information to anybody,
but doing so seems appropriate in this situation. Which of the following could be taking
place? - Answers - Social engineering attack
, What is a transaction in a database? - Answers - A group of statements that either
succeed or fail as a whole
Why is system testing performed? - Answers - To test individual systems for
vulnerabilities
What is the primary determination as to whether an incident is included in a business
continuity plan (BCP)? - Answers - Probability of occurrence and impact
A business continuity plan (BCP) program manager within a large organization: -
Answers - Usually manages multiple BCP projects.
What step of a business continuity plan (BCP) comes after providing training? -
Answers - Testing and exercising plans
Having supplies on hand for continued production: - Answers - may conflict with other
organizational planning principles.
Which term is defined as "an element necessary to perform the mission of an
organization"? - Answers - CSF
What is the primary purpose of identifying critical resources in the business impact
analysis (BIA) process? - Answers - Identify all IT assets that support critical business
functions (CBFs).
Lower recovery time objectives (RTOs) are __________ but __________. - Answers -
achievable, costly
What are critical resources? - Answers - Those that are required to support critical
business functions (CBFs)
Functionality testing is primarily used with: - Answers - Software development
A(n) ____________ assessment attempts to identify vulnerabilities that can be
exploited. - Answers - Exploit
A business continuity plan (BCP) is an example of a(n): - Answers - Security Plan
Which of the following is most likely to describe how to perform test restores? - Answers
- A backup plan
Which of the following is not a common category of control implementation? - Answers -
Functional
What characteristic is common to risk assessments and threat assessments? - Answers
- They are both performed for a specific time.
2026
Another term for data range and reasonableness checks is: - Answers - input validation
Which of the following is not one of the three primary objectives of controls? - Answers -
Eliminate
What changes plaintext data to ciphered data? - Answers - Encryption
A hacker wants to launch an attack on an organization. The hacker uses a tool to
capture data sent over the network in cleartext, hoping to gather information that will
help make the attack successful. What tool is the hacker using? - Answers - A packet
analyzer
Primary considerations for assessing threats based on historical data in your local area
are __________ and ___________. - Answers - weather conditions, natural disasters
In a SQL injection attack, an attacker can: - Answers - read sections of a database or a
whole database without authorization.
What does the principle of least privilege have in common with the principle of need to
know? - Answers - They both specify that users be granted access only to what they
need to perform their jobs.
An access control such as a firewall or intrusion prevention system cannot protect
against which of the following? - Answers - Social engineering
What is the purpose of nonrepudiation techniques? - Answers - To prevent people from
denying they took actions
Background checks, software testing, and awareness training are all categories of: -
Answers - procedural controls.
Ideally, when should you perform threat modeling? - Answers - Before writing an
application or deploying a system
You receive an email from someone named Bob in the IT department who needs to
access your login information for a scheduled internal vulnerability assessment. You
know an assessment is taking place because your manager notified your group last
week. Normally, you wouldn't give your password or other login information to anybody,
but doing so seems appropriate in this situation. Which of the following could be taking
place? - Answers - Social engineering attack
, What is a transaction in a database? - Answers - A group of statements that either
succeed or fail as a whole
Why is system testing performed? - Answers - To test individual systems for
vulnerabilities
What is the primary determination as to whether an incident is included in a business
continuity plan (BCP)? - Answers - Probability of occurrence and impact
A business continuity plan (BCP) program manager within a large organization: -
Answers - Usually manages multiple BCP projects.
What step of a business continuity plan (BCP) comes after providing training? -
Answers - Testing and exercising plans
Having supplies on hand for continued production: - Answers - may conflict with other
organizational planning principles.
Which term is defined as "an element necessary to perform the mission of an
organization"? - Answers - CSF
What is the primary purpose of identifying critical resources in the business impact
analysis (BIA) process? - Answers - Identify all IT assets that support critical business
functions (CBFs).
Lower recovery time objectives (RTOs) are __________ but __________. - Answers -
achievable, costly
What are critical resources? - Answers - Those that are required to support critical
business functions (CBFs)
Functionality testing is primarily used with: - Answers - Software development
A(n) ____________ assessment attempts to identify vulnerabilities that can be
exploited. - Answers - Exploit
A business continuity plan (BCP) is an example of a(n): - Answers - Security Plan
Which of the following is most likely to describe how to perform test restores? - Answers
- A backup plan
Which of the following is not a common category of control implementation? - Answers -
Functional
What characteristic is common to risk assessments and threat assessments? - Answers
- They are both performed for a specific time.